CVE-2026-104971: Plane: Cross-Workspace Asset Duplication IDOR + WorkspaceFileAssetEndpoint and FileAssetEndpoint Missing Authorization

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, DuplicateAssetEndpoint fetches a source FileAsset without limiting it to the caller's workspace, allowing cross-workspace asset duplication. WorkspaceFileAssetEndpoint and the legacy FileAssetEndpoint omit workspace authorization, allowing authenticated users to read, create, modify, or delete assets in workspaces where they are not members. Separately, WorkspaceViewViewSet.retrieve lacks the authorization decorator used by its sibling actions, exposing an unauthorized workspace-view read surface. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit these issues?

An authenticated Plane user can exploit the affected asset and workspace-view endpoints. For the asset issues, the user does not need to be a member of the workspace containing the targeted assets.

2

What access could an attacker gain or abuse?

An attacker could duplicate a file asset from another workspace, and could read, create, modify, or delete assets in workspaces where they are not a member. They may also read workspace-view data through the affected retrieve action.

3

Are unauthenticated deployments affected?

The described attack paths require an authenticated user with low privileges; no user interaction is required. The provided information does not identify any configuration prerequisite beyond running a Plane version prior to 1.4.0.

4

What is the remediation?

Upgrade Plane to version 1.4.0, which fixes the reported authorization flaws. The provided information does not specify a workaround if upgrading cannot be performed immediately.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203